LinuxQuestions.org
Did you know LQ has a Linux Hardware Compatibility List?
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices

Reply
 
Search this Thread
Old 07-09-2008, 07:42 PM   #1
chaz_bro1972
Member
 
Registered: Jul 2006
Location: Oklahoma, USA
Distribution: Slackware 14.0
Posts: 96

Rep: Reputation: 16
Angry rkhunter output help


I have used rkhunter and chkrootkit to check my system for rootkits. Chkrootkit finds nothing, while rkhunter has listed some 'warnings' for me. I have no idea what I am supposed to do with these warnings. Are they false positives? Are they evidence of rootkits? I don't have a clue.

If you want to check out these warnings, go here

Searching Google just gives me a headache. I keep getting different users who use different distros other than Slackware.

People on IRC are no help at all.

Any help at all would be a nice change of pace. If all you can do is say "Search Google", then do not even bother responding.

Thank you.
 
Old 07-09-2008, 08:00 PM   #2
bgeddy
Senior Member
 
Registered: Sep 2006
Location: Liverpool - England
Distribution: slackware64 13.37 and -current, Dragonfly BSD
Posts: 1,810

Rep: Reputation: 227Reputation: 227Reputation: 227
The warnings are just warning you about settings that are standard to a stock Slackware setup - they are nothing to worry about.

The scripts mentioned are supposed to be scripts, the services activated are on by default in /etc/inetd.conf and the stock setup file /etc/ssh/sshd_config comments out the PermitRootLogin setting.

So, again, nothing to worry about.

I'd recommend reading http://www.slackbook.org/ to get acquainted with your system.
 
Old 07-09-2008, 09:00 PM   #3
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,123

Rep: Reputation: 151Reputation: 151
If you have sshd and inetd running I'd suggest a couple of changes.

On the Slackware 12.0 box I'm looking at now, PermitRootLogin defaults to yes, so you should set it to no. The Protocol setting defaults to 2,1 and should be set to 2. I've also commented out all except the services I actually use in /etc/inetd.conf (imaps and cvspserver on this box).
 
Old 07-11-2008, 11:08 AM   #4
simcox1
Member
 
Registered: Mar 2005
Location: UK
Distribution: Slackware
Posts: 794
Blog Entries: 2

Rep: Reputation: 30
You can also ask questions regarding rkhunter on their mailing list. You'll probably see someone has already asked this question before anyway. This is a link to the project page on sourceforge.

http://rkhunter.sourceforge.net/

The link to the users mailing list is on the right.
 
Old 07-11-2008, 02:00 PM   #5
chaz_bro1972
Member
 
Registered: Jul 2006
Location: Oklahoma, USA
Distribution: Slackware 14.0
Posts: 96

Original Poster
Rep: Reputation: 16
Thank you kindly for all this assistance. It's nice to know there is still this helpful community for Linux users.

bgeddy & gilead: fixed those things, and it looks better now - THANKS!

simcox1: Thanks you for the link. Nice to know about these places to go. I wasn't aware of the mailing list, until now.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
RKhunter Help please Golgo13 Linux - Software 3 01-16-2008 04:27 PM
RkHunter Output - Opinion Please jim.thornton Linux - Security 15 01-15-2008 10:52 AM
rkhunter lumiwa Linux - Newbie 1 09-17-2007 08:51 PM
rkhunter atlaika Linux - Security 7 11-29-2005 10:47 AM
rkhunter phatbastard Linux - Security 3 12-08-2004 09:44 PM


All times are GMT -5. The time now is 07:47 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration